Application Security

Repo ManagerNew

Provides security governance over your code repositories — tracking exposed secrets, vulnerable dependencies, branch protection compliance, and developer access controls.

Repo Manager

Source code repository security and governance

What it does

Key capabilities

Secret Detection

Scans repository history for exposed API keys, credentials, and tokens — including commits already pushed.

Dependency Vulnerability

Tracks vulnerable third-party packages across all repositories with severity scoring and fix recommendations.

Branch Protection Audit

Verifies branch protection rules are in place — no direct pushes to main, required code review, signed commits.

Access Governance

Reviews developer access rights across repositories, flagging over-privileged users and inactive accounts.

Cross-Repo Visibility

Unified view across GitHub, Azure DevOps, and Bitbucket repositories in one security dashboard.

Commit Activity Monitoring

Tracks unusual commit patterns that may indicate insider threat or compromised developer accounts.

Highlights

Why Repo Manager?

  • Secret scanning including historical commits
  • Dependency vulnerability across all repos
  • Branch protection compliance verification
  • Developer access rights governance
  • GitHub, Azure DevOps, and Bitbucket supported
Included in OneView

Repo Manager is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.

24/7 Support Available
Phone: +27 060 984 1210
FAQs

Frequently asked questions

Repo Manager scans entire repository commit histories — not just the current HEAD — for patterns matching API keys, access tokens, private keys, database connection strings, and cloud provider credentials. This is critical because developers often commit credentials that are later removed from HEAD but remain visible in git history indefinitely.

Repo Manager integrates with GitHub (cloud and Enterprise Server), Azure DevOps, and Atlassian Bitbucket. All three platforms are scanned through read-only API credentials — no repository configuration changes are required. Results are normalised into a single unified view across all repository platforms.

Repo Manager verifies that your main/production branches have branch protection rules enforced — specifically: no direct pushes without a pull request, at least one required code reviewer, status checks must pass before merge, and optionally that commits are signed. Branches without these protections are flagged as a security risk.

ISO 27001 Annex A.8.4 and A.8.28 require secure development practices and controls on access to source code. Repo Manager's secret detection, dependency vulnerability scanning, branch protection audit, and developer access review together provide documented evidence of SDL controls — specifically the technical measures that prevent vulnerable or credential-exposing code from reaching production.

See Repo Manager in action

Request a personalised demo and we'll show you exactly how Repo Manager works within your environment.